← back
CVE-2026-20931highobserved exploitationCWE-73

Windows Telephony Service Elevation of Privilege Vulnerability

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 8epss 0.9%
from disclosure to weapon
Published on NVDJan 13
VulnCheck+42d
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
yesVulnCheck
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C